1---2name: inf1n1tydes0ul-oneinfinity-docs3description: One&Infinity — Skill Boundaries4---5# One&Infinity — Skill Boundaries67Defines what this system does well, what it does not, and where accuracy limits apply.89---1011## What the System Is Good At1213### Confirmed Working (Validated in Codebase)1415| Capability | Confidence |16|-----------|-----------|17| Secret scanning in GitHub repos with ownership attribution | HIGH |18| Multi-tool result normalization (nuclei, dalfox, sqlmap, subfinder, httpx) | HIGH |19| SHA-256 fingerprint-based finding deduplication (cross-tool) | HIGH |20| 6-pattern exploit chain detection from confirmed findings | HIGH |21| CVSS 3.1 scoring from vector strings | HIGH |22| Subdomain enumeration via subfinder/assetfinder + HTTP probing | HIGH |23| Adaptive recon (tech detection, JS endpoint extraction, cloud asset discovery) | HIGH |24| SQLite-backed finding persistence with WAL journaling | HIGH |25| Multi-format report export (JSON, Markdown, HTML, PDF) | HIGH |26| System health diagnostics (doctor command, 10-point scoring) | HIGH |27| Scope validation (wildcard/CIDR/always-OOS rules) | HIGH |28| GitHub org-to-domain intelligence mapping | HIGH |29| Finding confidence classification — confirmed/unverified/false_positive/simulated | HIGH |30| CLI reproduction command generation per finding (ReproducibilityMapper) | HIGH |31| Cross-run persistent payload intelligence (PersistentMemory JSON store) | HIGH |32| ROI-driven URL scoring and target prioritization (BountyStrategyEngine) | HIGH |33| Elite hunting strategies — aggressive / stealthy / high-value | HIGH |34| Post-hunt benchmarking against reference findings (precision/recall/F1) | HIGH |3536### Probabilistic / Best-Effort3738| Capability | Confidence | Notes |39|-----------|-----------|-------|40| Live secret validation (GitHub, Stripe, OpenAI, Slack, Redis, Postgres) | MEDIUM | Read-only; 3-second hard timeout per credential |41| XSS validation via canary reflection | HIGH | Requires target to reflect input |42| SQLi validation via error patterns + timing | MEDIUM | 4-second timing threshold; network jitter can cause false negatives |43| SSRF validation via metadata probe patterns | MEDIUM | Only detects reflected metadata, not blind SSRF |44| Secret ownership attribution (first-party vs. third-party) | MEDIUM | Heuristic: org name matching + static mappings |45| Exploit chain PoC generation | MEDIUM | Steps beyond the trigger vuln are synthesized, not validated |46| AI red team prompt evolution | MEDIUM | Depends on LLM API availability and target cooperation |4748---4950## What the System Is NOT Good At5152- **Blind SSRF without out-of-band callback**: The validator checks for metadata reflection; blind SSRF requires external collaborators (Burp Collaborator, interactsh).53- **Stored XSS validation**: Only reflected XSS is automated; stored XSS requires a separate rendering step.54- **DOM XSS validation**: The `browser_analysis` pipeline phase uses Playwright for DOM XSS sink analysis, but validation of confirmed DOM XSS still requires manual review — the engine detects potential sinks, not confirmed exploitability.55- **Authenticated endpoint testing**: The scanner does not handle session management, CSRF tokens, or multi-step login flows automatically.56- **Rate limit bypass**: No automatic detection of WAF rate limiting on specific endpoints.57- **Zero-day discovery without prior pattern**: The zero-day engine uses anomaly heuristics (timing, status changes, reflection), not novel vulnerability classes.58- **Network-level vulnerabilities**: No port scanning correlation with findings; nmap integration generates scripts but doesn't auto-parse results into the graph.59- **Mobile dynamic analysis without device**: Frida/Objection require a rooted/jailbroken device or emulator connected at runtime.6061---6263## Accuracy Boundaries6465### Secret Detection66- **False positive rate**: ~15% for `generic_api_key` type (keyword-only match). High-specificity types (AWS, GitHub PAT, Stripe) have ~5% FP rate.67- **False negative rate**: Secrets in binary files, encrypted archives, or obfuscated code are not detected.68- **Entropy threshold**: 3.8 bits/char for short strings, 4.5 for strings >64 chars.6970### Vulnerability Validation71- **XSS confirmation rate**: ~90% of reflected XSS found by dalfox are confirmed by the canary method.72- **SQLi error-based confirmation**: ~85% for MySQL/PostgreSQL; lower for MSSQL (different error patterns).73- **Timing-based SQLi**: ~70% true positive rate due to network jitter.74- **Confidence classifier thresholds**: `confirmed` requires ≥ 0.70 confidence + evidence/payload present; below 0.35 is automatically classified `false_positive` and excluded from reports. AI-theory findings are always capped at `unverified` (max 0.40 confidence) regardless of source confidence.75- **Tool-source bonus**: Findings from tool-confirmed sources receive +0.15 confidence before threshold evaluation.7677### Exploit Chains78- Only 6 predefined patterns. Multi-hop chains beyond these patterns are not automatically detected.79- Chain detection fires when ANY finding with the trigger vuln type exists (medium+ severity) — it does NOT verify that the specific finding is actually exploitable.80- Chain findings generated by `ExploitChainEngine` are tagged `source_type=simulated` and classified as `simulated` by `FindingClassifier` — they are excluded from submitted reports unless independently confirmed by `ExploitChainExecutor` HTTP execution.8182---8384## Supported Use Cases85861. **Bug bounty reconnaissance and hunting** — primary design target872. **Authorized penetration testing** — requires `scope.yaml` with `authorized: true`883. **GitHub secret intelligence** — OSINT on public repos for target domains894. **CI/CD integration** — results via JSON export, `gen_report.py` for HTML output905. **Security research** — research mode with theory generation + anomaly detection9192---9394## Unsupported Use Cases9596- Unauthorized scanning of systems without written authorization97- Production credential validation beyond read-only API checks98- Social engineering or phishing infrastructure99- DoS or denial-of-service testing